But here I started ntopng without the -e flag and I got 3562 packets on port 9200 in a minute and a half.
sudo /usr/local/bin/ntopng -U ntop -ip4p1 -D all -E all -A 2 -H -n 1 -F"es;flows;ntopng2-%Y.%m.%d;http://localhost:9200/_bulk" -d/var/lib/ntop -w 3000 -n 1 -m 192.168.0.0/16,10.0.0.0/8,172.16.0.0/12
09/Jun/2015 10:34:11 [src/Prefs.cpp:685] Using ElasticSearch for data dump [flows][ntopng2-%Y.%m.%d][http://localhost:9200/_bulk]
Tue Jun 9 10:33:08 EDT 2015
P301002:~
$ sudo tcpdump -w test1.pcap -X -s1500 -nnli lo port 9200
tcpdump: listening on lo, link-type EN10MB (Ethernet), capture size 1500 bytes
^C3562 packets captured
7126 packets received by filter
0 packets dropped by kernel
Tue Jun 9 10:34:29 EDT 2015
The pcap file is attached as test1.pcap.gz
Here I started ntopng same command but with the -e flag.
$ sudo /usr/local/bin/ntopng -e -U ntop -ip4p1 -D all -E all -A 2 -H -n 1 -F"es;flows;ntopng2-%Y.%m.%d;http://localhost:9200/_bulk" -d/var/lib/ntop -w 3000 -n 1 -m 192.168.0.0/16,10.0.0.0/8,172.16.0.0/12
09/Jun/2015 10:50:40 [src/Prefs.cpp:685] Using ElasticSearch for data dump [flows][ntopng2-%Y.%m.%d][http://localhost:9200/_bulk]
09/Jun/2015 10:50:40 [src/Prefs.cpp:793] Logging into /var/lib/ntop/ntopng.log
09/Jun/2015 10:50:40 [src/Ntop.cpp:781] Setting local networks to 192.168.0.0/16,10.0.0.0/8,172.16.0.0/12
09/Jun/2015 10:50:40 [src/Redis.cpp:93] Successfully connected to redis 127.0.0.1:6379@0
09/Jun/2015 10:50:40 [pro/NtopPro.cpp:100] ERROR: [LICENSE] Invalid or missing ntopng License [Empty license file]
09/Jun/2015 10:50:40 [pro/NtopPro.cpp:111] WARNING: [LICENSE] ntopng will now run in pro mode for 10 minutes
09/Jun/2015 10:50:40 [pro/NtopPro.cpp:113] WARNING: [LICENSE] before returning to community mode
09/Jun/2015 10:50:40 [pro/NtopPro.cpp:114] WARNING: [LICENSE] You can buy a permanent license at http://shop.ntop.org
09/Jun/2015 10:50:40 [pro/NtopPro.cpp:115] WARNING: [LICENSE] or run ntopng in community mode starting
09/Jun/2015 10:50:40 [pro/NtopPro.cpp:116] WARNING: [LICENSE] ntopng --community
09/Jun/2015 10:50:40 [src/Ntop.cpp:755] Parent process is exiting (this is normal)
Tue Jun 9 10:50:40 EDT 2015
After about 5 minutes I stopped ntopng and the packet capture - 8 packets captured.
Tue Jun 9 10:49:45 EDT 2015
P301002:~
$ sudo tcpdump -w test2.pcap -X -s1500 -nnli lo port 9200
tcpdump: listening on lo, link-type EN10MB (Ethernet), capture size 1500 bytes
^C8 packets captured
16 packets received by filter
0 packets dropped by kernel
Tue Jun 9 10:56:09 EDT 2015
here is the data:
$ tcpdump -r test2.pcap -nn
reading from file test2.pcap, link-type EN10MB (Ethernet)
10:51:27.908125 IP 127.0.0.1.60295 > 127.0.0.1.9200: Flags [.], ack 116553322, win 537, options [nop,nop,TS val 104525777 ecr 104450777], length 0
10:51:27.908141 IP 127.0.0.1.9200 > 127.0.0.1.60295: Flags [.], ack 1, win 529, options [nop,nop,TS val 104525777 ecr 100040817], length 0
10:52:42.908074 IP 127.0.0.1.60295 > 127.0.0.1.9200: Flags [.], ack 1, win 537, options [nop,nop,TS val 104600777 ecr 104525777], length 0
10:52:42.908084 IP 127.0.0.1.9200 > 127.0.0.1.60295: Flags [.], ack 1, win 529, options [nop,nop,TS val 104600777 ecr 100040817], length 0
10:53:57.908048 IP 127.0.0.1.60295 > 127.0.0.1.9200: Flags [.], ack 1, win 537, options [nop,nop,TS val 104675777 ecr 104600777], length 0
10:53:57.908066 IP 127.0.0.1.9200 > 127.0.0.1.60295: Flags [.], ack 1, win 529, options [nop,nop,TS val 104675777 ecr 100040817], length 0
10:55:12.908331 IP 127.0.0.1.60295 > 127.0.0.1.9200: Flags [.], ack 1, win 537, options [nop,nop,TS val 104750777 ecr 104675777], length 0
10:55:12.908347 IP 127.0.0.1.9200 > 127.0.0.1.60295: Flags [.], ack 1, win 529, options [nop,nop,TS val 104750777 ecr 100040817], length 0
Tue Jun 9 10:57:33 EDT 2015